VYPR
Medium severity6.5NVD Advisory· Published Apr 24, 2023· Updated Jun 17, 2026

CVE-2023-1624

CVE-2023-1624

Description

The WPCode WordPress plugin before 2.0.9 has a flawed CSRF when deleting log, and does not ensure that the file to be deleted is inside the expected folder. This could allow attackers to make users with the wpcode_activate_snippets capability delete arbitrary log files on the server, including outside of the blog folders

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:wpcode:wpcode:*:*:*:*:*:wordpress:*:*
    Range: <2.0.9
  • WordPress/WPCodedescription
  • WordPress/WPCodellm-fuzzy
    Range: <2.0.9

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.